Skip to content
inionline.net
  • Managed IT Support Services
  • Contact Us
inionline.net
  • Blog

    CISA Flags LiteSpeed cPanel Plugin Flaw Exploited for Root Privilege Escalation

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a security flaw impacting LiteSpeed cPanel Plugin to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by June 18, 2026. The vulnerability in question is CVE-2026-54420 (CVSS score: 8.5), which has been described as a case…

    Read More CISA Flags LiteSpeed cPanel Plugin Flaw Exploited for Root Privilege EscalationContinue

  • Blog

    Chinese Hackers Abused Google Workspace Rules to Steal Research and Defense Emails

    A China-linked espionage group hid inside North American medical, academic, and military research networks for more than a year, quietly stealing sensitive research and defense email. The way in was a backdoor on their REDCap research servers that stole login credentials. The exfiltration was the unusual part: the attackers rewired the victims’ own Google Workspace…

    Read More Chinese Hackers Abused Google Workspace Rules to Steal Research and Defense EmailsContinue

  • Blog

    North Korean Hackers Are Turning Developer Tools Into Malware Delivery Channels

    Cybersecurity researchers have flagged two malicious cyber campaigns that exhibit similarities with a persistent North Korean threat cluster known as Contagious Interview (aka Famous Chollima, HexagonalRodent, and Void Dokkaebi). According to a report published by Proofpoint, the threat actor has been found orchestrating phishing campaigns using developer role recruitment or code review themes

    Read More North Korean Hackers Are Turning Developer Tools Into Malware Delivery ChannelsContinue

  • Blog

    Copilot ‘SearchLeak’ Attack Allows 1-Click Data Theft

    The critical, three-stage attack is now patched, but it’s part of a new group of AI prompt-injection issues that use hidden URLs and other variables.

    Read More Copilot ‘SearchLeak’ Attack Allows 1-Click Data TheftContinue

  • Blog

    China-Nexus Actor Spied on US Researchers Undetected for a Year

    Google discovered and disrupted the sprawling campaign, which stole RedCAP credentials to target numerous institutions and exfiltrate sensitive data.

    Read More China-Nexus Actor Spied on US Researchers Undetected for a YearContinue

  • Blog

    Most CISOs Report Pressure to Bury Bad Security News

    Executive leaders may not be saying it aloud, but business objectives and priorities don’t always promote timely disclosures.

    Read More Most CISOs Report Pressure to Bury Bad Security NewsContinue

  • Blog

    LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers

    A default low-privilege account on a LiteLLM proxy can climb to full admin and run code on the server by chaining three vulnerabilities, researchers at Obsidian Security disclosed LiteLLM is a widely deployed open-source AI gateway that brokers calls to more than 100 model providers behind one OpenAI-compatible interface. A server takeover exposes every provider…

    Read More LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway ServersContinue

  • Blog

    One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes

    A single click on a trusted Microsoft link could have let an attacker pull emails, calendar details, and indexed files out of Microsoft 365 Copilot Enterprise Search. Researchers at Varonis Threat Labs chained three bugs into a one-click exfiltration path they call SearchLeak. Because the link pointed to a real microsoft.com domain, traditional anti-phishing and…

    Read More One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA CodesContinue

  • Blog

    The Beginning of the End of Social Engineering

    AI-native operating systems are shifting the responsibility to stay vigilant against social engineering cyberattacks from the user onto the system itself.

    Read More The Beginning of the End of Social EngineeringContinue

  • Blog

    ⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and More

    Stuff broke again. Not in a movie way. An old tool was left exposed. An abandoned package was abused. A deprecated feature was still running in prod. This week is the same lesson in a new form: phishing kits are easier to rent, AI names are useful bait, old login paths still fail, and forgotten…

    Read More ⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and MoreContinue

Page navigation

Previous PagePrevious 1 … 4 5 6 7 8 … 499 Next PageNext
Facebook
Privacy Policy
Background by Vecteezy

Web Design 2024 SekuritasIT

Veteran Owned and Operated

Scroll to top
  • Managed IT Support Services
  • Contact Us